Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

NAIC 668 Compliance Checklist: What Your Information Security Program Needs

August 11, 2026
hero-naic-668-compliance-checklist-1.png

A NAIC 668 compliance checklist covers four requirements set out in Section 4 of the model law. This guide breaks each one into plain steps you can act on.

This checklist assumes you already know the law applies to you. If you’re not sure yet, start with what NAIC Model Law 668 actually is or check whether your state has adopted it.

If you’re a Chicagoland insurer, agency, or MGA, you’re already on the clock.

Key Takeaways

  • Build a written Information Security Program covering administrative, technical, and physical safeguards for Nonpublic Information, scaled to your size and complexity.
  • Investigate every Cybersecurity Event using a written incident response plan, not an ad hoc scramble.
  • Notify your state Commissioner within 72 hours of determining a Cybersecurity Event occurred, when the notification triggers apply to you.
  • Certify compliance in writing every February 15 and keep supporting records for five years.

The Information Security Program: What You Have to Build

Section 4C and 4D of the model law spell out the building blocks of your Information Security Program. Here’s each requirement translated into plain English, with a note on what it typically looks like inside a small agency or insurer.

RequirementWhat the Law RequiresWhat It Looks Like in a Small Agency
Named responsible personYou must designate a person responsible for the program.Often the owner or office manager, named in writing, not necessarily a dedicated security hire.
Written risk assessmentIdentify foreseeable internal and external threats, assess their likelihood and damage, and reassess at least annually.A short written document reviewed once a year and updated after any major change.
Access controls and MFALimit access to Authorized Individuals and use effective controls, which may include Multi-Factor Authentication.MFA turned on for email, cloud file storage, and any system holding Nonpublic Information.
Encryption in transit and at restEncrypt Nonpublic Information sent over external networks and stored on portable devices.Encrypted email for client files, plus encrypted laptops and phones.
Secure disposalDocument procedures for securely disposing of Nonpublic Information.A shredding policy for paper and a wipe procedure for retired hard drives.
Testing and monitoringTest and monitor systems regularly for intrusions.Managed detection tooling and periodic vulnerability scans, usually run by an IT partner.
Audit trailsMaintain audit trails able to detect and reconstruct Cybersecurity Events.Centralized logging kept long enough to investigate an incident after the fact.
Environmental safeguardsProtect against fire, water damage, and other environmental hazards.Fire suppression in a server room, or simply moving servers to a cloud provider that already handles this.

Every item on this table has to be “commensurate with the size and complexity” of your business.

The Governance Layer: Who Signs Off and When

Section 4 doesn’t stop at technical controls. It also requires oversight from the top of the organization, not just the IT department.

RequirementWhat It RequiresWhen It’s Due
Board or committee reportIf you have a board, it (or a committee) must require management to report in writing at least annually on the program’s status, risk assessment, testing results, and any Cybersecurity Events.At least once a year.
Written incident response planCover your internal response process, roles and decision-making authority, communications, remediation, documentation, and plan review after an event.In place before an event happens, not written during one.
Annual certificationSubmit a written statement to the Commissioner certifying Section 4 compliance, and retain supporting records for examination.Every February 15, records kept five years.

The board-report and certification requirements exist for the same reason: the model law wants compliance to be a leadership decision with a paper trail, not something that lives only in an IT ticketing system. If your program has gaps, the certification requirement doesn’t disappear. You document the remedial work planned and underway instead of leaving the box unchecked.

Who Owns What: IT Partner vs. Your Leadership Team

Not every item on the checklist above belongs to the same person. Some of it is a technical build. Some of it is a leadership decision that no vendor can make for you.

Section 4 RequirementWho Typically Owns ItWhy
Access controls and MFAIT/MSP partnerConfiguring and maintaining login controls is a technical build.
Encryption in transit and at restIT/MSP partnerRequires the right tools, set up correctly, and kept current.
Testing and monitoringIT/MSP partnerNeeds ongoing tooling and someone watching the alerts.
Audit trailsIT/MSP partnerCentralized logging is infrastructure work.
Environmental safeguardsIT/MSP partnerOften solved by moving to a cloud provider that already handles it.
Secure disposal proceduresSharedIT executes the wipe or shred; leadership sets the written policy.
Named responsible personYour leadershipThe law requires a designated person, not a vendor’s name on a contract.
Written risk assessmentYour leadership (IT-informed)Leadership owns the sign-off even when IT supplies the technical findings.
Board or committee reportYour leadershipOnly your board can report to your board.
Third-party vendor due diligenceYour leadershipYou choose and vet your own vendors, including your IT partner.
Written incident response planSharedIT builds the technical response; leadership owns roles and decision authority.
Annual certification to the CommissionerYour leadershipOnly an officer of the licensee can certify compliance.

A managed IT partner can operate most of the technical rows in that table day to day. LeadingIT’s insurance and compliance IT services are built around exactly those Section 4 categories: MFA and access controls, encryption, monitoring, logging, and secure disposal. What a vendor cannot do is sign your certification or sit on your board. Those rows stay with you no matter who you hire.

This split matters because examiners under Section 7 don’t just check whether MFA is turned on. They check whether the paperwork behind it, the risk assessment, the board report, the vendor due-diligence file, actually exists. A good IT partner helps produce that documentation. It’s still your name on the certification.

The Exemption Trap: “We’re Exempt” Doesn’t Mean “We’re Done”

Icon grid showing the three groups Section 9 exempts from building a full Information Security Program: licensees with fewer than 10 employees, licensees already compliant with the HIPAA Security Rule, and employees or agents already covered by another licensee's program.

Section 9 of the model law exempts three groups from building a full Information Security Program: licensees with fewer than 10 employees (including contractors), licensees already compliant with HIPAA’s security rules, and employees or agents already covered by another licensee’s program.

Even a licensee exempt under Section 9 must still submit a written certification claiming the exemption. Exemption is not the same as no paperwork.

That last point trips up a lot of small agencies. The HIPAA exemption in particular requires an affirmative written certification of that HIPAA compliance. You can’t just assume the exemption applies and move on. You have to document it.

There’s also a clock most people miss. If your agency grows past 10 employees, or you drop out of HIPAA compliance, you don’t get to keep operating under the old exemption indefinitely. You get 180 days to come into full Section 4 compliance from the moment you stop qualifying.

A few situations where the exemption trap shows up in practice:

  • An agency hires its 10th employee or contractor and doesn’t realize the clock started.
  • A licensee lets its HIPAA compliance lapse (a missed risk analysis, an expired BAA) without noticing the NAIC 668 exemption lapsed with it.
  • An agent assumes their carrier’s program covers them, when the relationship doesn’t actually meet the Section 9(C) carve-out.

If you’re not certain which category you fall into, that’s worth resolving before February 15, not after.

See Where You Stand

Not sure if your current setup would hold up under a Section 7 examination? Answer 8 plain-English questions and see your compliance-readiness level and the specific gaps to fix. No sign-up required to see your result.

Take the free 2-minute NAIC 668 Risk-Check

Frequently Asked Questions

As promptly as possible, and no later than 72 hours from determining a Cybersecurity Event occurred. Your notification needs to cover specifics like when it happened, how you found it, and what data was affected.

Yes. The model law requires you to reassess the effectiveness of your key controls, systems, and procedures no less than annually. It doesn’t have to be a massive undertaking every time, but it can’t be a one-time document you file away.

You’re exempt from building the full Information Security Program under Section 9, but you still have to submit a written certification claiming that exemption. Fewer than 10 employees, including contractors, is the threshold. If you cross it, you have 180 days to build a compliant program.

You qualify for an exemption from the full Section 4 program, but only if you certify that HIPAA compliance in writing. It’s not automatic. And if your HIPAA compliance lapses for any reason, you have 180 days to come into full NAIC 668 compliance from that point.

You get 180 days from the point you stop qualifying to build and implement a full Section 4 Information Security Program. That includes the risk assessment, the security measures, the incident response plan, and everything else on this checklist. The clock doesn’t wait for your next renewal date.

Each insurer domiciled in an adopting state must submit a written statement to the Commissioner by February 15 each year, certifying compliance with Section 4. You also have to keep the supporting records, schedules, and data for five years in case the Department examines them.

No. It’s a model law, not a federal statute, so it only takes effect once a state adopts it, and the exact citation and enforcement details vary by state. If you operate in multiple states, check each one’s adoption status separately.

Building Your Program Without Building It Alone

Most of this checklist is achievable with the right IT partner handling the technical rows and your leadership owning the governance rows. The hard part is usually documentation, not technology.

LeadingIT works with Chicagoland insurance agencies, MGAs, and insurers on the technical side of Section 4: access controls, MFA, encryption, monitoring, audit trails, and secure disposal, plus the documentation an examiner would ask to see. See our insurance compliance IT services or book a call to walk through where your program stands today. Questions first?

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.